Umbra Wiki cve cve/CVE-2026-21533
Back to wiki

CVE-2026-21533 — Microsoft Windows Improper Privilege Management Vulnerability

provenance: imported · CVE: CVE-2026-21533

CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Windows
Date added 2026-02-10
Due date 2026-03-03
Ransomware campaign use Unknown

Description

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21533

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-21533
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog